Back to Landing Page SECURE PATIENT PRIVACY ENCLAVE

Privacy Policy

Last Updated: July 2026 — This document explains how Diagnostics AI, Inc. collects, protects, stores, and handles your professional and Protected Health Information (PHI). Includes comprehensive GDPR and CCPA/CPRA privacy policies.

DOCUMENT ARTICLES
ZERO-KNOWLEDGE PRINCIPLE

No Model Training

As a strict matter of compliance, clinical inputs, prompts, and Patient Data uploaded to Premedice are NEVER used to train or improve third-party foundation models.

✳︎

1. Scope & Application

Diagnostics AI, Inc. ("we," "us," "our") is committed to protecting the privacy and security of your personal data and patient health information. This Privacy Policy ("Policy") describes how Diagnostics AI, Inc. collects, uses, processes, stores, shares, and protects your information when you access or use the Premedice platform ("Platform").

This Policy covers all data collected through the Platform, including data you provide directly, data collected automatically, and data received from third-party sources. Depending on your location, additional rights and protections may apply. If you are a covered entity or business associate under HIPAA, our Business Associate Agreement (BAA) supplements this Policy.

This Policy is incorporated by reference into our Terms and Conditions. Capitalized terms used but not defined here have the meanings assigned in the Terms.

✳︎

2. Information We Collect

We collect only the information necessary to provide and improve our medical AI platform:

  • Account Information: Full name, email, professional credentials, license numbers, institutional affiliation, specialty, and authentication tokens.
  • Patient Data (PHI): Medical histories, clinical notes, lab results, medications, allergies, imaging studies (CT, MRI), pathology reports, and vital signs you upload.
  • Usage Data: Conversation transcripts with AI models, click streams, feature interactions, and search histories.
  • Device & Technical Data: IP address, geolocation (approximate), browser, OS type, and audit logs.
  • Payment Data: Subscription details and invoice history. Stripe secure tokens are used for cards; we do not store full card digits.
  • Communication Data: Support tickets, email correspondence, and feedback submissions.
✳︎

3. How We Collect Information

We collect information through: direct input (account setup, file uploads, patient metrics); automatic logs (cookies, session preferences); third-party authentications (Google OAuth profile details); AI model interaction (conversation content processed in real-time); document processing (automated extraction from uploaded files); and payment processors (Stripe confirmation).

✳︎

4. How We Use Your Information

We use information exclusively for providing medical AI outputs, improving model accuracy (via aggregated, de-identified parameters), technical support, fraud prevention, regulatory compliance, billing invoicing, and clinical research (subject to separate explicit consent). We do not use your data for advertising, profiling, or any purpose not listed in this Policy.

AI Model Scope: Premedice exclusively uses text-based and clinical AI models. The Platform does not use generative image AI models or generative video AI models. No images or videos are generated by our systems. All AI processing is limited to text-based clinical analysis, lab report interpretation, and medical information retrieval.

5. GDPR Compliance Policy

This section constitutes our GDPR Privacy Policy as required by Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation). It applies specifically to data subjects located in the European Economic Area (EEA), the United Kingdom (UK), and Switzerland.

5.1 Data Controller

Diagnostics AI, Inc., a Delaware corporation, is the data controller for personal data collected through the Platform. Our EU representative for GDPR Article 27 purposes can be contacted at eu-representative@premedice.com. Our UK representative can be contacted at uk-representative@premedice.com.

5.2 Legal Bases for Processing (Article 6 GDPR)

We process your personal data under the following legal bases:

  • Contractual Necessity (Article 6(1)(b)): Processing necessary to perform our contract with you under the Terms, including AI processing, document analysis, account management, and service delivery.
  • Legitimate Interests (Article 6(1)(f)): Processing for our legitimate interests in maintaining network and information security, fraud prevention, service improvement through aggregated analytics, and legal compliance. We conduct legitimate interest assessments (LIAs) for each processing activity.
  • Consent (Article 6(1)(a)): Where we rely on consent, it is freely given, specific, informed, and unambiguous. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
  • Legal Obligation (Article 6(1)(c)): Processing necessary to comply with legal obligations, including breach notification, regulatory record-keeping, and responding to valid legal requests.
  • Vital Interests (Article 6(1)(d)): In exceptional circumstances, processing may be necessary to protect someone’s vital interests (e.g., emergency access to patient data in life-threatening situations).

5.3 Special Category Data (Article 9 GDPR)

Health data, genetic data, and biometric data qualify as special categories under Article 9 GDPR. We process such data under Article 9(2)(h) — processing necessary for the provision of healthcare, treatment, or management of health systems, subject to appropriate safeguards. Our safeguards include:

  • Strict role-based access controls limiting access to authorized personnel.
  • AES-256 encryption at rest and TLS 1.3 in transit.
  • Pseudonymization where feasible.
  • Immutable audit trails of all access to special category data.
  • Data minimization practices ensuring only clinically necessary data is processed.
  • Annual Data Protection Impact Assessment (DPIA) reviews.

5.4 Data Protection Officer

We have appointed a Data Protection Officer (DPO) as required by Articles 37-39 GDPR. Our DPO oversees our data protection strategy, conducts DPIAs, handles data subject requests, and serves as our contact point for supervisory authorities. The DPO can be reached at dpo@premedice.com.

5.5 Data Protection Impact Assessment

We have conducted a Data Protection Impact Assessment (DPIA) under Article 35 GDPR for our AI processing activities involving large-scale processing of special category health data. The DPIA addresses: systematic description of processing, necessity and proportionality assessment, risk assessment for data subject rights and freedoms, and mitigation measures. DPIAs are reviewed annually and updated when processing activities materially change.

5.6 Records of Processing Activities

We maintain a Register of Processing Activities (ROPA) under Article 30 GDPR, documenting all processing activities involving personal data of EEA/UK data subjects. The ROPA includes: purposes of processing, categories of data subjects and personal data, categories of recipients, international transfer mechanisms, retention periods, and technical security measures.

5.7 International Transfers (Articles 44-49 GDPR)

For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on:

  • Standard Contractual Clauses (SCCs): Module 2 (controller-to-processor) and Module 3 (processor-to-processor) SCCs adopted by European Commission Decision 2021/914.
  • Transfer Impact Assessments (TIAs): Conducted for each data destination as required by the Schrems II decision, assessing local surveillance laws and available redress mechanisms.
  • Supplementary Measures: End-to-end encryption, restricted access controls, pseudonymization, and contractual prohibitions on secondary use.
  • UK Addendum: For UK transfers, the UK International Data Transfer Agreement (IDTA) supplements the EU SCCs.
  • EU-US Data Privacy Framework (DPF): Where applicable, we rely on the DPF for transfers to certified US organizations.

5.8 Data Breach Notification (Articles 33-34 GDPR)

In the event of a personal data breach, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (Article 33 GDPR).
  • Notify affected data subjects without undue delay where the breach is likely to result in high risk to their rights and freedoms (Article 34 GDPR).
  • Document all breaches, including facts, effects, and remedial actions, in our internal breach register (Article 33(5) GDPR).
✳︎

6. GDPR Data Subject Rights

If you are located in the EEA, UK, or Switzerland, you have the following rights under the GDPR. We will respond to all valid requests within 30 calendar days (extendable by up to 60 days for complex requests, with notice of extension):

  • Right of Access (Article 15): You may request confirmation of whether we process your personal data, and if so, access to that data and information about processing purposes, categories of data, recipients, retention periods, and your other rights. We provide the first copy free of charge.
  • Right to Rectification (Article 16): You may request correction of inaccurate or incomplete personal data without undue delay.
  • Right to Erasure (“Right to be Forgotten”) (Article 17): You may request deletion of your personal data where it is no longer necessary, you withdraw consent, you object, processing is unlawful, or deletion is required by law. This right is subject to legal retention obligations under applicable law.
  • Right to Restriction of Processing (Article 18): You may request restriction of processing while a dispute about accuracy, lawfulness, or our legitimate interests is being resolved. Restricted data is stored but not further processed.
  • Right to Data Portability (Article 20): You may receive your personal data in a structured, commonly used, machine-readable format (JSON, CSV), and have it transmitted directly to another controller where technically feasible.
  • Right to Object (Article 21): You may object to processing based on legitimate interests or for direct marketing. We will cease processing unless we demonstrate compelling legitimate grounds overriding your interests.
  • Right to Withdraw Consent (Article 7(3)): Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
  • Right to Lodge a Complaint (Article 77): You have the right to lodge a complaint with your local supervisory authority. Contact details for major authorities: ICO (UK, ico.org.uk), CNIL (France, cnil.fr), DPC (Ireland, dataprotection.ie), BfDI (Germany, bfdi.bund.de).
  • Right to Compensation (Article 82): You have the right to claim compensation for material or non-material damage resulting from a violation of the GDPR.

To exercise any of these rights, contact us at privacy@premedice.com or dpo@premedice.com. We may request additional information to verify your identity before processing your request. We will not discriminate against you for exercising your rights.

✳︎

7. Data Sharing & Disclosure

We do NOT sell or trade your personal data. We disclose data only to: contractually bound AI Model Providers (Google Cloud, OpenAI, Anthropic) who are forbidden from using data for foundation model training; our secure GCP hosting provider; payment processors (Stripe); or to comply with law and court orders. All recipients are bound by Data Processing Addendums compliant with Article 28 GDPR.

✳︎

8. Third-Party Sub-Processors

We engage the following compliant sub-processors:

  • Google Cloud Platform (GCP) — Server hosting and compute. SOC 2 Type II, HIPAA-eligible.
  • Google Vertex AI — Secure MedLM and Gemini model infrastructure. DPA in place.
  • OpenAI & Anthropic — Zero data-retention API endpoints for supplemental models. No training on customer data.
  • Stripe, Inc. — PCI-Level 1 certified transaction processing.
  • Sentry, Logflare & Resend — Error tracking (sans PHI), logging, and notification dispatches.

We update this list as sub-processors change. Enterprise customers receive 30 days notice before new sub-processors are engaged.

Independence Disclaimer

Premedice is an independent product and is not affiliated with, endorsed by, or sponsored by Google, OpenAI, Anthropic, or any other AI model provider. We integrate these third-party services through our proprietary Health Smart AI Engine to deliver clinical decision support. All trademarks and brand names belong to their respective owners.

✳︎

9. International Data Transfers

For transfers from the EEA, UK, or Switzerland, we utilize standard contractual clauses (SCCs) approved by the European Commission, combined with strict supplementary security measures, transfer impact assessments (TIAs), and encryption of all payloads in transit. Data residency options are available for enterprise customers subject to additional fees.

✳︎

10. Data Security

Our infrastructure features AES-256 encryption at rest and TLS 1.3 in transit. We implement strict Role-Based Access Controls (RBAC) with Multi-Factor Authentication (MFA), continuous weekly vulnerability scanning, annual independent SOC 2 Type II audits, and 24/7 security monitoring. Production environments run inside private VPC enclaves with intrusion detection and DDoS protection.

✳︎

11. Data Retention & Deletion

Patient Data is retained for the duration of your active subscription plus 90 days for data export. Upon deletion requests or account closing, records are permanently erased from live servers within 30 days and backup rings within 180 days, compliant with NIST SP 800-88 guidelines. Logs of model chats are de-identified after 12 months. Audit logs are retained for 1-7 years for regulatory compliance.

✳︎

12. Your Rights & Choices

Depending on your location, you have rights to access, rectify, delete, restrict, or port your data. You may object to processing, withdraw consent, or file a complaint with supervisory bodies (such as the ICO or CNIL) at any time. We will process requests within 30 calendar days. Submit requests to privacy@premedice.com.

13. CCPA/CPRA Compliance Policy

This section constitutes our California Privacy Policy as required by the California Consumer Privacy Act of 2018 (CCPA) as amended by the California Privacy Rights Act (CPRA) (Cal. Civ. Code §§ 1798.100-1798.199.100). It applies specifically to residents of the State of California.

13.1 Categories of Personal Information Collected (Past 12 Months)

We have collected the following categories of personal information from California residents within the past 12 months:

  • Identifiers: Name, email address, IP address, online identifiers, Google OAuth ID.
  • Professional & Employment Information: Professional credentials, license numbers, institutional affiliation, specialty.
  • Protected Health Information (PHI): Medical histories, clinical notes, lab results, medications, imaging data, and other health information you upload (Cal. Civ. Code § 1798.140(v)).
  • Internet & Electronic Network Activity: Browsing history, search history, interaction with the Platform, AI conversation transcripts.
  • Geolocation Data: Approximate IP-based location (not precise GPS).
  • Sensory Data: Where voluntarily provided in uploaded documents (images, medical scans).
  • Inferences: Clinical observations and insights derived from AI analysis of your data.
  • Sensitive Personal Information: Health data, including medical history, mental health information, genetic data (CPRA § 1798.140(ae)).

13.2 Sources of Personal Information

We collect personal information from the following categories of sources: (a) directly from you (account registration, file uploads, communications); (b) from your devices and browser (automatic technical data); (c) from Google (authentication); (d) from your EHR or healthcare IT systems (with authorization); and (e) from public research databases (at your direction).

13.3 Business or Commercial Purposes for Collection

We collect personal information for the following business purposes: service provision and personalization; AI processing and analysis; quality improvement and product development; security monitoring and fraud prevention; compliance with legal and regulatory obligations; auditing (including HIPAA compliance audits); debugging and technical support; and short-term transient use.

13.4 Categories of Third Parties with Whom We Share

We disclose personal information for a business purpose to the following categories of third parties: AI model providers (Google Cloud, OpenAI, Anthropic); cloud infrastructure providers (GCP); payment processors (Stripe); professional service providers (Sentry, Logflare, Resend); and law enforcement or government entities (as required by law).

13.5 No Sale of Personal Information

We do NOT sell personal information as defined by the CCPA (Cal. Civ. Code § 1798.140(ad)). We have no actual knowledge of selling personal information of minors under 16 years of age. We do NOT share personal information for cross-context behavioral advertising. We have not sold or shared any personal information in the preceding 12 months.

13.6 Sensitive Personal Information Usage

We use sensitive personal information (health data) only for purposes reasonably expected by an average consumer: service provision, security, and compliance. We do not use sensitive personal information for: (a) inferring consumer characteristics, (b) cross-context behavioral advertising, (c) short-term transient use (except for service provision), (d) profiling in furtherance of adverse decisions.

You have the right to limit the use of your sensitive personal information to purposes necessary for service provision. We already limit sensitive PI use to such purposes, and this limitation is automatic.

13.7 Retention Periods

We retain each category of personal information for the following periods: identifiers and account information (for the duration of your account plus 90 days); PHI (for the duration of your account plus 90 days, then deletion); usage data (12 months, then de-identification); audit logs (minimum 1 year, maximum 7 years); billing records (7 years for tax compliance).

✳︎

14. CCPA Rights & Request Process

If you are a California resident, the CCPA and CPRA provide you with the following specific rights regarding your personal information:

  • Right to Know (Cal. Civ. Code § 1798.110): You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share information.
  • Right to Delete (Cal. Civ. Code § 1798.105): You have the right to request deletion of personal information we have collected about you, subject to exceptions (completing transactions, detecting security incidents, complying with legal obligations).
  • Right to Correct (Cal. Civ. Code § 1798.106): You have the right to request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing (Cal. Civ. Code § 1798.120): We do not sell or share personal information. If our practices change, we will provide notice and an opt-out mechanism.
  • Right to Limit Use of Sensitive PI (Cal. Civ. Code § 1798.121): You may request limitation on our use of sensitive personal information to purposes necessary for service provision. This limitation is already in effect for our Platform.
  • Right to Non-Discrimination (Cal. Civ. Code § 1798.125): We will not discriminate against you for exercising any CCPA rights, including by denying services, charging different prices, or providing different service quality.

Request Submission & Verification

To exercise your CCPA rights, submit a request to privacy@premedice.com or via the Privacy Request form in your account settings. We will verify your identity by matching the information you provide with the information in our records. We may request additional information if we cannot verify your identity with reasonable certainty. Authorized agents may submit requests on your behalf with written authorization signed by you and proof of identity.

Response Timing & Metrics

We will acknowledge receipt of your request within 10 business days and respond substantively within 45 calendar days (extendable by an additional 45 days for complex requests, with notice of extension). We maintain records of CCPA requests received, complied with (in whole or in part), denied, and the mean days to respond, updated annually. You may request our CCPA metrics for the preceding calendar year.

Contact for CCPA Inquiries

CCPA inquiries may be directed to: privacy@premedice.com, Attn: CCPA Request, Premedice, 23 A P C Road, Loan Office Para, Barandi, Jessore Sadar, Jessore, 7400, BD. You also have the right to file a complaint with the California Attorney General at oag.ca.gov.

✳︎

15. Virginia, Colorado, Connecticut, Utah & Iowa Rights

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and Iowa (ICDPA) have rights to access, correct, delete, port personal data, and opt-out of targeted advertising and profiling. Appeals of adverse decisions must be processed within 60 days. We do not engage in profiling with legal or similarly significant effects as defined by these state laws.

✳︎

16. International Privacy Rights

We adhere to international compliance framework principles including PIPEDA in Canada (10 privacy principles: Accountability, Identifying Purposes, Consent, Limiting Collection, Limiting Use/Disclosure/Retention, Accuracy, Safeguards, Openness, Individual Access, Challenging Compliance); LGPD (Law 13,709/2018) in Brazil (rights to confirmation, access, correction, anonymization, portability, deletion, and opposition); APPI in Japan; PDPA in Singapore; PIPA in South Korea; Australia Privacy Act 1988 (APPs); POPIA in South Africa; India DPDP Act 2023; Mexico LFPDPPP (ARCO rights); and China PIPL. Mandated regional guidelines take full precedence where relevant.

✳︎

17. Automated Decision-Making & Profiling

All algorithmic classifications, symptoms parses, and timelines are assistive guides. Because every output requires independent validation by a licensed doctor prior to patient implementation, we do not engage in solely automated decisions that produce legal or significant clinical consequences. You have the right to human intervention, expression of your point of view, and contestation of any automated decision (Article 22 GDPR).

✳︎

18. Cookies & Tracking Technologies

We employ only functional, secure cookies needed for maintaining active login states (session cookies) and CSRF prevention. We do not place advertising pixels, cross-site trackers, or marketing trackers on our Platform. Local browser storage is strictly used for client-side state caching. Essential cookies cannot be disabled without affecting functionality. Cookie duration: session cookies expire on browser close; preference cookies expire after 12 months.

✳︎

19. Children's Privacy

Our platform is for licensed practitioners or adult medical researchers aged 18 or above. We do not collect identifiers from children under 13 under COPPA. Healthcare providers uploading pediatric records are responsible for holding valid parental consent in their offline files. If we become aware of data from individuals under 18, we will immediately delete it.

✳︎

20. Data Breach Notification Procedures

Our response framework matches global mandates: we notify relevant supervisory authorities under GDPR within 72 hours, covered entities under HIPAA without unreasonable delay (within 60 days), affected California residents under CCPA without undue delay, and affected individuals without undue delay in high-impact events. Our internal target for all notifications is within 48 hours.

✳︎

21. HIPAA Compliance (United States)

Diagnostics AI, Inc. executes Business Associate Agreements (BAAs) with covered entity customers. To maintain absolute ePHI integrity, we provide granular role-based permissions (minimum necessary access), encrypt databases end-to-end (AES-256), retain audit trails for 6 years, and conduct mandatory annual HIPAA training. Our GCP infrastructure is HIPAA-eligible with BAA coverage. We maintain SOC 2 Type II reports available under NDA.

✳︎

22. Sensitive Data & Special Categories

Health records, genetic details, and clinical data qualify as special categories under GDPR Article 9 and as sensitive data under other applicable laws. We handle these files under strict medical-exemption safeguards, maintaining high encryption standards, pseudonymization, and restricting access to certified workforce members. We do not collect precise GPS location, biometric data for identification, or criminal conviction data.

✳︎

23. Changes to This Policy

This Privacy Policy may be updated to reflect feature improvements or regulatory updates. We supply at least 30 days advance notice for material changes via email or dashboard banners. Continued use after the 30-day window indicates acceptance. Archived versions are available upon request.

✳︎

24. Contact & Data Protection Officer

For rights execution, privacy inquiries, or BAA requests, reach out below:

Privacy Division

GDPR, HIPAA, CCPA claims & data subject requests

privacy@premedice.comdpo@premedice.com

EU Representative

eu-representative@premedice.com

GDPR Article 27

UK Representative

uk-representative@premedice.com

UK GDPR

Premedice

Attn: Privacy Team
23 A P C Road, Loan Office Para,
Barandi, Jessore Sadar,
Jessore, 7400, BD

Supervisory Authorities

ICO (UK): ico.org.uk
CNIL (France): cnil.fr
DPC (Ireland): dataprotection.ie
California AG: oag.ca.gov